PT-2026-50710 · Autogpt · Autogpt

·

CVE-2026-55237

·

Published

2026-06-18

·

Updated

2026-06-18

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:L
Name of the Vulnerable Software and Affected Versions AutoGPT versions prior to 0.6.62
Description A DOM-based Cross-Site Scripting (XSS) issue exists on the signup page. The application improperly trusts the next URL parameter, which is passed to the router.push() function. This allows an attacker to craft a malicious link that, when opened by an authenticated user, performs a client-side redirect and executes arbitrary JavaScript in the browser context. Potential impacts include credential theft, internal network pivoting, and unauthorized actions performed on behalf of the victim.
Recommendations Update to version 0.6.62.

Exploit

Fix

Open Redirect

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55237
GHSA-J2CP-JG5Q-38WJ

Affected Products

Autogpt